Skip to content

feat(linux): prove the native enforcement substrate - #45

Merged
tumberger merged 20 commits into
mainfrom
feat/linux-policy-substrate
Sep 1, 2026
Merged

tumberger merged 20 commits into
mainfrom
feat/linux-policy-substrate

Conversation

@tumberger

@tumberger tumberger commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add the private sandy-linux backend with deterministic planning, ambient preparation, and irreversible application phases.
  • Construct a private filesystem view, isolate blocked networking, remove capabilities, and freeze topology with seccomp.
  • Require Landlock ABI 6 and always scope signals to the sandbox domain.
  • Enter private user, mount, and IPC namespaces so host System V IPC objects are not exposed.
  • Replace the inherited session keyring with an anonymous ring and deny key-management syscalls.
  • Reject external pathname-socket grants and other unrepresentable policy combinations instead of weakening them.

Security properties

  • Preparation exercises namespace, keyring, and modern mount prerequisites in a sacrificial child; enforcement failure requires immediate termination.
  • Sources are pinned before enforcement, reopened after namespace entry, and matched by device, inode, type, and link count before mounting.
  • Write-protected regular files with pre-existing hard-link aliases are rejected.
  • Filesystem reads do not imply execution; inherited host noexec restrictions are never cleared.
  • Sandbox descendants may signal within their domain but cannot signal unrelated same-user host processes.
  • Live tests prove host System V IPC identifiers and inherited session keys are unusable after enforcement.
  • No host procfs process tree, former root, or non-granted siblings survive in the private view.
  • All Linux unsafe and native calls are isolated in crates/linux/src/ffi.rs; safe descriptor inputs use lifetime-bound BorrowedFd.
  • Process-disabled mode preserves threads while blocking process creation and namespace operations.
  • Internal error phases are exhaustive, and the prepared sandbox carries an actionable must_use contract.

Verification

  • cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
  • Linux x86-64 and arm64 native enforcement tests with hard timeouts
  • cargo test --workspace --locked
  • cargo deny check
  • make package-check

This branch intentionally leaves the supported facade returning Unsupported on Linux. The next stacked branch wires the proven backend into sandy::apply().

@tumberger
tumberger marked this pull request as ready for review September 1, 2026 08:54
@greptile-apps

greptile-apps Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Greptile Summary

The PR adds a private Linux enforcement backend that separates deterministic policy planning, ambient preparation, and irreversible application.

  • Builds a private filesystem view using namespaces, pinned mount sources, runtime aliases, and pivot_root.
  • Applies Landlock, capability removal, seccomp filtering, keyring isolation, and optional network namespace isolation.
  • Adds Linux enforcement tests and x86-64/arm64 CI coverage while leaving the supported Linux facade behavior unchanged.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains.

Important Files Changed

Filename Overview
crates/linux/src/prepare.rs Pins and verifies filesystem sources, validates mount shapes, prepares protections, and now excludes protected compatibility aliases from materialization.
crates/linux/src/plan.rs Rejects policy combinations that the Linux backend cannot represent, including confidential descendants inside visible recursive grants.
crates/linux/src/mount.rs Constructs the private mount tree, applies read-only overlays, creates admitted runtime aliases, and removes the former root.
crates/linux/src/apply.rs Orders irreversible namespace, filesystem, Landlock, capability, and seccomp enforcement phases.
crates/linux/src/ffi.rs Centralizes the backend’s Linux native and unsafe operations behind safe Rust interfaces.
crates/linux/tests/live_linux.rs Adds live enforcement coverage for the backend’s filesystem, IPC, keyring, networking, and process restrictions.
.github/workflows/ci.yml Adds Linux substrate linting and live tests on x86-64 and arm64 runners.

Sequence Diagram

sequenceDiagram
    participant Caller
    participant Plan as Linux policy planner
    participant Prepare as Ambient preparation
    participant Namespace as Namespace isolation
    participant Mount as Private filesystem
    participant Landlock
    participant Caps as Capabilities
    participant Seccomp
    Caller->>Plan: plan(validated policy)
    Plan-->>Caller: LinuxPolicyPlan
    Caller->>Prepare: prepare(plan, working directory)
    Prepare-->>Caller: PreparedLinuxSandbox
    Caller->>Namespace: apply prepared sandbox
    Namespace->>Mount: repin and construct private root
    Mount->>Landlock: enter restricted filesystem view
    Landlock->>Caps: apply access rules
    Caps->>Seccomp: remove capabilities
    Seccomp-->>Caller: enforcement complete
Loading

Reviews (4): Last reviewed commit: "fix(linux): preserve cross-platform plan..." | Re-trigger Greptile

Comment thread crates/linux/src/prepare.rs Outdated
@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger

Copy link
Copy Markdown
Contributor Author

@greptile

@tumberger
tumberger merged commit ad20aca into main Sep 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant